6 ms·
I put off adding TLS certs to my personal website for years. It's just a few static files served by nginx on a server - there wasn't a great reason to bother, I
by dangerlibrary 3y ago
I put off adding TLS certs to my personal website for years. It's just a few static files served by nginx on a server - there wasn't a great reason to bother, I thought.
It took me almost exactly 3 minutes start to finish with letsencypt. Where 'start' was "I should stop putting that off" and typing "letsencrypt.com" into a browser, and 'finish' was nginx serving up https:// https:// on all my domains. I'm genuinely curious what nginx could possibly do to improve the situation there.
- joseph_grobbles 3y ago[dead]
- fs111 3y agoCheck what caddy does. I think that is what op is after
- guraf 3y agoIt's true that setup is simple enough but what other servers like Caddy provide is automated renewals. You don't have to mess with having a .well-known always accessible on each domain, for example. Caddy does it for you and only when it's needed.
- bombcar 3y agoCaddy does it all automatically and you don’t have to remember to do things by hand.
- adobrawy 3y agoCaddy targets single instances. No coordination is required to avoid receiving receive multiple certificates for multiple instances for same domain. Nginx has a profit from big business that would require coordination to avoid multiple certificates. For comparison, it is worth noting that to ensure such coordination, Traefik requires an Enterprise plan and a separate agent. Such a business also often has mechanisms for storing certificates, so they do not necessarily want to integrate it into Nginx.
- francislavoie 3y agoWith Caddy, you can cluster easily by either sharing its filesystem data storage across machines, or configuring a different storage driver (redis, consul, db, etc.) and they will automatically coordinate for cert issuance. Caddy writes a lock file to the storage which prevents multiple instances from stepping on eachother's toes.
- bg24 3y agoI recently moved to Caddy. Out-of-the-box TLS, HTTP3, Dumbed-down simple configuration, static files... it has been a breath of fresh air.
- rekoil 3y agoCaddy is amazing. Still irritated that they ship it with an unprotected admin endpoint enabled by default on localhost:2019 that eats JSON and allows reconfiguration of the webserver like adding new sites that enable further attacks. Put "{ admin off }" as a separate block in the root Caddyfile to disable it.
- francislavoie 3y agoOur view is that localhost:2019 is inherently protected though - that only allows requests from the same machine. If you're running the machine with shared users, then of course it's up to you to further secure things. That said, see https://github.com/caddyserver/caddy/issues/5317 https://github.com/caddyserver/caddy/issues/5317, we are considering changing the default, but that would be a breaking change although it would likely be a transparent change for most users. The default that makes the most sense depends on the platform and installation method, which is why it's complicated.
- rekoil 3y agoSSRF is a thing, just because you trust the code doesn't mean you've eliminated all security risks. The tools we use in the industry should all have secure defaults. Glad to hear you're considering changing the default! It would be enough for me if Caddy generated a password (that's hard for attackers to predict) on first launch, set that in a config file it has write access to (autosave.json for example), and then required Basic auth using this password unless the configuration specified otherwise. My problem is that this endpoint is entirely unauthenticated.
- Gordonjcp 3y agoLots of folk have mentioned Caddy, but I'd like to also mention Traefik which kind of does the same thing but I found it to be less of a pain in the arse.
- berkle4455 3y agoTraefik has a very verbose config with non-sensible defaults; Caddy works out of the box with 1-3 lines to setup your domain and sensible defaults. What's the pain?
- v3ss0n 3y agoTarefik because it is better architectured, auto discovery of docker services , battle tested
- fulafel 3y agoLink for others curious about the discovery: https://doc.traefik.io/traefik/providers/docker/ https://doc.traefik.io/traefik/providers/docker/ (but preferring Caddy so far)
- francislavoie 3y agoThat can be done with Caddy as well: https://github.com/lucaslorentz/caddy-docker-proxy https://github.com/lucaslorentz/caddy-docker-proxy
- Gordonjcp 3y agoThis didn't work when I tried Caddy before, and it was the entire thing I needed to do. I should revisit Caddy and see how it gets on.
- Gordonjcp 3y agoIt didn't cope with services starting and stopping well, and couldn't provision services from docker (at least when I looked at it).